Table of Contents
With Univention Corporate Server 4.0-1, the first point release of Univention Corporate Server (UCS) 4.0 is now available. It provides various improvements and bugfixes. An overview of the most important changes:
The Debian Wheezy point update 7.8 has been integrated.
The Free for personal use edition license has been extended to 50 users and 50 clients.
Improvements in the appliance mode allow a simpler system installation and setup of UCS systems.
Joining an Active Directory domain has been simplified.
Multiple bugfixes and improvements related to Samba, e.g. in the printer support and when using Microsoft SharePoint.
Several enhancements and bugfixes in design and usability of the Univention Management Console.
During the update some services in the domain may not be available, i.e. the update should occur in a maintenance window. It is recommended to test the update in a separate test environment prior to the actual update. The test environment should be identical to the production environment. Depending on the system performance, network connection and the installed software the update takes between 20 minutes and several hours.
In environments with more than one UCS system, the update order of the UCS systems must be borne in mind:
The authoritative version of the LDAP directory service is maintained on the master domain controller and replicated on all the remaining LDAP servers of the UCS domain. As changes to the LDAP schemes can occur during release updates, the master domain controller must always be the first system to be updated during a release update.
Starting with UCS 4.0 UCS, installation DVDs are only provided for the x86 64 bit architecture (amd64). Existing 32 bit UCS 3 systems can still be updated to UCS 4.0 through the online repository or by using update DVDs. The 32 bit architecture will be supported over the entire UCS 4 maintenance.
It must be checked whether sufficient disk space is available. A standard installation requires a minimum of 6 GB of disk space. Depending on the scope of the existing installation, the update will require about another 2 GB of disk space for downloading and installing all packages.
For the update, a login should be performed on the system's local console as user
root
, and the update should be initiated there. Alternatively, the
update can be conducted using Univention Management Console.
Remote updating via SSH is not recommended as this may result in the update procedure
being cancelled, e.g., if the network connection is interrupted. In consequence, this can affect
the system severely. If updating should occur over a network connection nevertheless, it must be
verified that the update continues despite disconnection from the network. This can be
done, e.g., using the tools screen
and at
.
These tools are installed on all system roles by default.
Following the update, new or updated join scripts need to be executed. This can be done in
two ways: Either using the UMC module univention-run-join-scripts
as user
root
.
The configuration of the UCS DNS name server BIND was prone to open resolver attacks,
which are used to launch Distributed Denial of Service (DDoS) attacks against other hosts
of the internet. To prevent such abuse the default configuration will be changed to allow
'recursive queries' only from IP addresses of the private address ranges, link-local
address ranges, localhost and local networks. If the name servers need to be queried from
any other hosts outside those network, they must be configured using the Univention Configuration Registry variable
dns/allow/query/cache
. This change gets only applied for
newly installed domain controllers. See SDB 1298 for
additional details to convert existing installations.
Subsequently the UCS system needs to be restarted.
The profile-based UCS network installation is not yet available in UCS 4.0-1. It will be provided at a later date. Please refer to our issue tracker for further details: Bug 35537.
Anonymous usage statistics on the use of Univention Management Console are collected when using the free for personal use version of UCS (which is generally used for evaluating UCS). The modules opened are logged in an instance of the web traffic analysis tool Piwik. This makes it possible for Univention to tailor the development of Univention Management Console better to customer needs and carry out usability improvements.
This logging is only performed when the free-for-personal-use license is used. The license status can be verified via the menu entry of the user menu in the upper right corner of Univention Management Console. If is listed under , this version is in use. When a regular UCS license is used, no usage statistics are collected.
Independent of the license used, the statistics generation can be deactivated by setting the
Univention Configuration Registry variable umc/web/piwik
to false.
WebKit, Konqueror and QtWebKit are shipped in the maintained branch of the UCS repository, but not covered with security support. WebKit is primarily used for displaying HTML help pages etc. Firefox should be used as web browser.
Univention Management Console uses numerous JavaScript and CSS functions to display the web interface. Cookies need to be permitted in the browser. The following browsers are recommended:
Chrome as of version 33
Firefox as of version 24
Internet Explorer as of version 9
Safari and Safari Mobile as of version 7
Users with older browsers may experience display or performance problems.
Listed are the changes since UCS 4.0-0:
All security updates issued for UCS 4.0-0 are included:
The Debian Wheezy update 7.8 has been integrated. It fixes several security issues in addition to the errata security issues already issued:
failed.ldif
file
exists (Bug 37291).
dns/allow/query/cache
. This change gets only applied for
newly installed domain controllers. See SDB 1298 for
additional details (Bug 37553).
umc/web/appliance/name
and umc/web/appliance/logo
(Bug 37488).
force printername
was activated implicitly during
modifications of existing print shares. Now it only gets activated on new print shares and if
the UCR variable samba/force_printername
is not set to no
or
false
(Bug 37123).
/etc/cron.daily/amavisd-new
) has been removed
(Bug 36928).
variable mail/antispam/headertag
can be used to define a
string to prepend to subject header field for SPAM messages. If the variable is unset
(default), the subject is not modified (Bug 36664).
pykotadmin.conf
Univention Configuration Registry template have been
fixed (Bug 36859).
apache2/ssl/v3
to true before or
after the update (Bug 36232).
mysql/autostart
(Bug 13811).
mail/saslauthd/cache/timeout
(default 1800) has been added
to define the saslauthd expiration time of the authentication cache (in seconds) (Bug 36949).
libvirtd
liveness check has been raised to 30 seconds (if the Univention Configuration Registry variable
libvirt/check/timeout
hadn't been modified locally (Bug 36605).
libvirt-check.sh
script output
(Bug 35069).
smb.conf
parameter spoolss: architecture
can be adjusted manually
by setting the new Univention Configuration Registry variable samba/spoolss/architecture
(see man
smb.conf
). On updated systems this UCR variable is maintained to keep the old default
(Bug 34068, Bug 37476).
cn=Subschema
and warn if Univention Directory Listener didn't
pass a entryUUID (Bug 36981).
Domain Admins
group in
Active Directory (Bug 35562, Bug 37168).
The following packages have been added to the maintained package repository (Bug 36467, Bug 36735, Bug 36609, Bug 37669, Bug 37288, Bug 36583):
join.log
(Bug 36290).
ucslint
module 0001 has been fixed. This traceback could appear if there were
problems while reading the join scripts of the source package (Bug 37688).